Skip to main content
Category: Compliance Program Governance

Quality Assurance

Also known as:
Simply put

Quality assurance (QA) is a systematic process for making sure that products, services, or processes consistently meet defined quality requirements and expectations. Rather than checking finished items after the fact, it focuses on establishing standards, guidelines, and procedures intended to prevent mistakes and defects in the first place.

Formal definition

Quality assurance is the part of quality management focused on providing confidence that defined quality requirements will be fulfilled, achieved through the systematic establishment of standards, guidelines, and procedures across the development and production of products, services, and processes. Its core purpose is preventive, to deter and reduce errors and defects, as distinct from quality control (QC), which is oriented toward inspecting or testing outputs against requirements. In this evidence QA is described as a general quality-management concept; its application to any specific regulatory or compliance context should be confirmed against the applicable framework.

Why it matters

Quality assurance matters because it shifts the focus of quality management from correcting problems after they occur to preventing them from arising in the first place. By establishing standards, guidelines, and procedures across the development and production of products, services, and processes, QA is intended to provide confidence that defined quality requirements will consistently be fulfilled. This preventive orientation can reduce the cost and disruption associated with detecting and remediating defects late in a process, when errors may be more difficult or expensive to fix.

In a compliance and financial crime context, the underlying logic of QA, systematic prevention rather than after-the-fact inspection, may be applied to processes and outputs where consistency against defined requirements is important. However, the evidence here describes QA as a general quality-management concept rather than a specific regulatory obligation. Its application to any particular AML, sanctions, or reporting framework should be confirmed against the applicable regulation or supervisory guidance, and QA should be understood as a measure to support and improve process quality rather than a guarantee that errors or defects will be eliminated.

Who it's relevant to

Quality and process managers
Professionals responsible for quality management use QA to establish the standards, guidelines, and procedures that provide confidence defined quality requirements will be fulfilled. Their focus is on designing processes that prevent defects rather than relying solely on end-stage inspection.
Compliance and operations teams
Teams that must produce consistent, requirement-driven outputs may draw on QA principles to build preventive controls into their processes. Because the evidence treats QA as a general concept, any application to a specific compliance framework should be confirmed against the applicable regulatory requirements.
Quality control practitioners
Those performing QC, which inspects or tests outputs against requirements, work alongside QA. Understanding the distinction helps ensure that preventive process controls and output-based testing are used together rather than confused with one another.

Inside QA

Sample-Based File Review
A core QA component involving the examination of a selected sample of completed work products, such as CDD files, transaction monitoring alert dispositions, or SAR/STR filing decisions, to assess whether they meet the organization's documented standards and applicable regulatory expectations. Sampling methodology (risk-based, random, or targeted) should be defined in advance, and the review typically evaluates completeness, accuracy, and consistency rather than re-performing the underlying investigation.
Quality Standards and Criteria
The documented benchmarks against which work is assessed, often derived from internal policies and procedures that operationalize obligations such as those under the US BSA and FinCEN rules, the UK Money Laundering Regulations and Proceeds of Crime Act, or the EU AML framework. QA measures adherence to these internal standards; it is an operational assurance function and not itself a source of legal obligation.
Feedback and Remediation Loop
A mechanism for communicating QA findings back to analysts, investigators, or first-line staff, and for tracking corrective actions such as file rework, retraining, or procedural clarification. This loop is intended to detect and address deficiencies and to support continuous improvement, not to guarantee error-free output.
Metrics and Trend Analysis
The aggregation of QA results into error rates, thematic findings, and trend reporting used to identify systemic weaknesses, training gaps, or control breakdowns across the AML program. Findings are typically escalated to management, the MLRO or equivalent compliance officer, and relevant governance committees.
Scope Definition
The delineation of which processes, obliged-entity functions, and work products fall within QA coverage (for example, KYC/CDD onboarding, EDD for higher-risk relationships, sanctions and PEP screening dispositions, or suspicious activity filing decisions) and which fall outside it. Scope may vary by jurisdiction, business line, and risk profile and should be documented explicitly.

Common questions

Answers to the questions practitioners most commonly ask about QA.

Is Quality Assurance the same as Quality Control in an AML program?
No, though the terms are sometimes used interchangeably in practice, they generally describe different functions. Quality Control (QC) typically refers to checks performed within a process to catch errors before an output is finalized, for example, a reviewer verifying an alert disposition or a SAR draft before submission. Quality Assurance (QA) generally refers to a broader, often independent review conducted after the fact to assess whether processes are operating as intended and producing consistent, defensible outcomes. The distinction can vary by institution, so firms should define both terms clearly in their internal procedures rather than assume a universal meaning.
Does passing a QA review mean a decision, such as closing an alert or filing a SAR, was correct?
Not necessarily. QA is a measure to assess and improve the consistency, adequacy, and documentation of decisions; it does not establish that any individual determination was objectively correct or that no financial crime occurred. A satisfactory QA outcome indicates that a decision was reasonable and properly supported on the information available at the time, not that it was infallible. Likewise, a QA finding that a decision was deficient reflects a process or documentation issue and does not, by itself, establish wrongdoing by any customer or staff member.
How does QA typically fit within the three lines of defense model?
QA can operate in different lines depending on how a firm structures it, and institutions should be explicit about placement to preserve independence. QA embedded within an operational team (for example, within investigations) is generally considered a first-line control. QA performed by the compliance function overseeing that activity may sit in the second line. This is distinct from internal audit, which typically provides third-line independent assurance. The key consideration is that reviewers should generally be sufficiently independent of the work they assess to provide credible challenge.
What activities within an AML program are commonly subject to QA review?
QA is typically applied across several AML processes, including transaction monitoring alert dispositions, customer due diligence and enhanced due diligence files, sanctions and PEP screening alert adjudications, and the quality and timeliness of suspicious activity or suspicious transaction reports (terminology varies by jurisdiction). The precise scope depends on the institution's risk profile, the obliged-entity activities it conducts, and its internal policy. Firms generally document which processes are in and out of scope rather than assuming QA covers every activity.
How can a firm select which cases to review through QA?
Approaches vary and are generally driven by a risk-based rationale. Common methods include random sampling to assess baseline consistency, risk-based or targeted sampling that weights higher-risk customers, products, or complex decisions, and full-population review for particularly sensitive determinations where volumes allow. Some firms combine methods. Sample sizes and selection criteria should generally be documented and calibrated to the firm's risk exposure, and exact sampling thresholds should be confirmed against internal policy rather than assumed.
What should a firm do with the findings identified through QA?
QA findings are generally intended to feed a feedback and remediation loop rather than serve only as a scoring exercise. Typical uses include remediating individual deficient cases where appropriate, identifying thematic or recurring issues, informing staff training and coaching, refining procedures and system tuning, and providing management information to governance forums. Documented tracking of findings to closure helps demonstrate that QA is used to detect and mitigate weaknesses, though it should be understood as a tool for managing risk rather than a guarantee that all errors are eliminated.

Common misconceptions

Quality Assurance and Quality Control (QC) are the same thing.
Although both aim to improve output quality, they are generally distinguished operationally. QC typically refers to checks embedded within a process (for example, a checker reviewing work before it is finalized), while QA generally assesses completed work after the fact to evaluate whether processes and standards are functioning as intended. Terminology can vary by organization and jurisdiction, so the specific meaning should be confirmed against internal policy.
Quality Assurance is the same as independent audit or regulatory examination.
QA is generally a first- or second-line operational assurance activity focused on the accuracy and consistency of day-to-day work products. Independent audit typically sits in a separate line of defense with broader independence and mandate. QA findings may inform, but do not replace, internal audit or examination by supervisory authorities.
A file passing QA review means no financial crime occurred or that the underlying decision was legally correct.
QA assesses whether work met documented internal standards and procedures; it is an operational measure to detect and mitigate deficiencies, not a determination of wrongdoing or its absence. A passed QA review does not establish that a customer is not engaged in illicit activity, and a filed SAR/STR that clears QA does not establish that any criminal offense occurred.

Best practices

Document QA scope, sampling methodology, and quality criteria in advance, and align them explicitly with the internal policies that operationalize applicable requirements (such as BSA/FinCEN rules, the UK MLRs and POCA, or the EU AML framework), noting that exact obligations vary by jurisdiction.
Apply a risk-based sampling approach that gives greater coverage to higher-risk work products, such as EDD files, higher-risk PEP or sanctions dispositions, and suspicious activity filing decisions, while documenting what falls outside the sample.
Maintain a clear separation between QA and the work being reviewed, so that reviewers are not assessing their own dispositions, and preserve the distinction between QA and independent internal audit.
Establish a structured feedback and remediation loop that tracks findings to closure through rework, targeted retraining, or procedural updates, rather than treating QA as a purely observational exercise.
Aggregate QA results into trend and thematic reporting and escalate systemic findings to the MLRO or equivalent compliance officer and relevant governance forums to support continuous improvement.
Frame QA outcomes as measures of adherence to internal standards, avoiding any characterization of a passed review as proof that no financial crime occurred or that a decision is legally conclusive.